google updater.exe

Google Inc

This is a setup program which is used to install the application. The file has been seen being downloaded from www.google.com.
Publisher:
Google Inc  (signed and verified)

MD5:
fa178884b6d8008d4c779a9c2e22c505

SHA-1:
22788f79d3b8b65cba3f75131bb0159d6804ed02

SHA-256:
5bced9eaf10cfca7f335e92677d37e44f6a6e054e178b5505d65ba3d6386e38e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
4/19/2024 2:19:29 PM UTC  (today)

File size:
1.2 MB (1,253,008 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\google updater.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/21/2010 7:00:00 PM

Valid to:
2/22/2012 6:59:59 PM

Subject:
CN=Google Inc, OU=Digital ID Class 3 - Java Object Signing, O=Google Inc, L=Mountain View, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
36B8DA6BF00D94F158301001ADD6527F

File PE Metadata
Compilation timestamp:
12/7/2010 12:25:35 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:ZhMdmGyYkwUisQE7PhSj5zmjrVU1hKCK2pcRnMXUEKMM6f14:DvZiC7zVKKEatEKMM6d4

Entry address:
0x11650

Entry point:
B8, 24, 0E, 97, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, B4, A5, BA, 7F, A7, 92, 42, D8, 75, 1F, 2A, EC, 5C, 92, B3, A0, C6, 2D, 10, 35, 34, 53, C8, E8, 4A, 6F, C1, B1, 11, 49, 39, B1, D1, A4, 95, 21, 09, 51, 9E, FF, 4D, 7B, 34, BA, 7B, CE, 31, 9F, A3, 34, E6, F7, A8, DA, 10, D8, 81, 19, BD, EB, AD, 06, 0D, E5, 09, 4D, 78, A6, 8C, B7, 51, 94, 00, D3, 2D, FE, 05, 75, 35, 89, 58, C6, C9, BF, C9, 3F, 08, A2, 9C, B6, FD, 2B, BC...
 
[+]

Packer / compiler:
PECompact v2

Code size:
111 KB (113,664 bytes)

The file google updater.exe has been seen being distributed by the following URL.